LFCS 2 🐧 Exam Format, Domains, and Scoring
The LFCS is a performance-based exam. You sit at a live terminal, on a real Linux system, and perform tasks. There is no list of answers to choose from. The system either matches the required state or it does not. Understanding how the exam is structured, how the domains are weighted, and how scoring works is the first step in preparing for it. This chapter covers the logistics, the domains, and the strategies that follow from them.
Key point: The LFCS is a 2-hour exam with 17–20 performance-based tasks and a passing score of 67%. It covers five domains: Operations Deployment (25%), Networking (25%), Storage (20%), Essential Commands (20%), and Users and Groups (10%). You can use man pages during the exam, and the tasks are graded by a script that checks the state of the system.
Why the exam format matters
The performance problem. The LFCS does not ask you to identify the correct command. It asks you to run it. The exam environment is a virtual machine with a terminal, and the tasks are real configuration changes: create a user, set up an LVM volume, configure a firewall rule, create a systemd service. The grading is automated. A script checks whether the system is in the expected state. If it is, the task is correct. If it is not, the task is wrong.
The time problem. Two hours for 17–20 tasks is roughly 6–7 minutes per task. Some tasks take one minute. Some take fifteen. The time budget is not generous, and getting stuck on one task costs the tasks you could have completed instead. The exam rewards speed and familiarity, not deep deliberation. Practice with a timer.
The documentation problem. The exam allows access to man pages. This is not a concession to memorization; it is a reflection of how system administrators actually work. You do not need to remember the exact flag for lvcreate if you know how to find it. The skill being tested is the ability to find the information and apply it, not the ability to recall it from memory.
The distribution problem. The exam is now distribution-independent. Earlier versions required you to select a platform at registration. The current exam removes that requirement and focuses on tasks that generalize across distributions . The commands are the same or similar across Ubuntu, CentOS, and other major distributions. The tasks are designed to be solvable with the standard tools that are present on any Linux system.
The partial credit problem. There is no partial credit for a partially correct task. A user that is created but has the wrong shell is a failed task. An LVM volume that is created but not mounted persistently is a failed task. The grading script checks the final state, not the effort. This is why verification is part of every task. After you perform the action, you check that it worked.
a. Exam format and logistics
The LFCS is delivered through PSI online proctoring using the PSI Secure Browser . You take it from your own computer, in a private room, with a proctor monitoring your screen, webcam, and microphone.
| Detail | Value |
|---|---|
| Duration | 2 hours (120 minutes) |
| Format | Performance-based tasks |
| Tasks | 17–20 |
| Passing Score | 67% |
| Cost | $395 (includes one retake) |
| Proctoring | PSI online |
| Validity | 24 months (policy effective April 2024) |
| Prerequisites | None |
| Documentation | man pages available |
The exam consists of 17–20 performance-based tasks . The tasks are graded by an automated script that checks the state of the system. The passing score is 67% . The exam is expected to take 2 hours.
The PSI Secure Browser is Chrome-based. Google Chrome is recommended for the best experience . You need a webcam that can be moved to pan the room, a microphone, and a reliable internet connection. A wired connection is more stable than wireless. You cannot have other applications running. The testing location must be clutter-free, with clear walls and adequate lighting .
You must present government-issued photo identification before the exam. The name on the ID must match the name on your registration. The exam is graded within 24 hours. If you pass, the certificate is available. If you do not pass, the retake option is available .
b. The five domains and their weights
The LFCS covers five domains. The weights determine how many tasks in each area you can expect. Operations Deployment and Networking together are half the exam. Storage and Essential Commands are another 40%. Users and Groups is the smallest at 10%.
| Domain | Weight |
|---|---|
| Operations Deployment | 25% |
| Networking | 25% |
| Storage | 20% |
| Essential Commands | 20% |
| Users and Groups | 10% |
Operations Deployment covers kernel parameters, process and service management, job scheduling, package management, failure recovery, virtual machines with libvirt, container engines, and SELinux .
Networking covers IPv4 and IPv6 configuration, hostname resolution, time synchronization, network troubleshooting, OpenSSH, packet filtering, port redirection, NAT, static routing, bridge and bonding devices, and reverse proxies .
Storage covers LVM, virtual filesystems, filesystem creation and troubleshooting, remote filesystems and network block devices, swap space, automounters, and storage performance monitoring .
Essential Commands covers Git operations, service creation and troubleshooting, system performance monitoring, application constraints, disk space troubleshooting, and SSL certificates .
Users and Groups covers local user and group management, environment profiles, resource limits, ACLs, and LDAP integration .
The domain weights are consistent across sources. The Linux Foundation’s official page lists Operations Deployment at 25%, Networking at 25%, Storage at 20%, Essential Commands at 20%, and Users and Groups at 10% . KodeKloud’s notes confirm the same weights .
c. Scoring and task strategies
The scoring is task-based. Each task is worth a portion of the total score, and the weights of the tasks correspond to the domain weights. A task in Operations Deployment may be worth more than a task in Users and Groups, but the exact per-task weighting is not published.
| Strategy | Reason |
|---|---|
| Verify every task | The grading script checks state |
| Do not get stuck | Time is limited |
Use man pages | Documentation is allowed |
| Practice with a timer | 6–7 minutes per task average |
| Persist changes | Many tasks require survival across reboot |
| Read the task twice | Misreading is the most common error |
Verification. After completing a task, verify that the system is in the expected state. For a user creation, check id username. For a service, check systemctl status. For a mount, check df -h and findmnt. For a firewall rule, check the firewall’s list output. The grading script does what you would do: it inspects the system. If your verification passes, the task likely passes.
Time management. The exam is 2 hours for 17–20 tasks. If a task is taking more than 10 minutes, move on and come back. A task you do not complete is a loss. A task you complete correctly is a gain. Spending 30 minutes on one task and running out of time for five others is a net loss even if the one task is correct.
Persistence. Many tasks require changes that survive a reboot. A mount that is not in /etc/fstab will not survive. A firewall rule that is not permanent will not survive. A user that is created is persistent by default. The task description usually indicates whether persistence is required. If it does not, assume it is.
Reading the task. The most common error is misreading the task. “Create a user with UID 1500” is different from “Create a user with UID 15000.” “Allow port 80” is different from “Allow port 8080.” Read the task completely before starting. Read it again after completing it to confirm you did what was asked.
Complete Example Session
# ============================================
# PART 1: EXAM LOGISTICS
# ============================================
Duration: 120 minutes
Tasks: 17–20
Passing Score: 67%
Cost: $395 (includes retake)
Proctoring: PSI Secure Browser
Validity: 24 months
Documentation: man pages available
# ============================================
# PART 2: DOMAIN WEIGHTS
# ============================================
Operations Deployment 25%
Networking 25%
Storage 20%
Essential Commands 20%
Users and Groups 10%
# ============================================
# PART 3: OPERATIONS DEPLOYMENT TASKS
# ============================================
- Configure kernel parameter persistently
- Troubleshoot a failing service
- Schedule a cron job
- Recover from a filesystem failure
- Create a container
# ============================================
# PART 4: NETWORKING TASKS
# ============================================
- Configure a static IP
- Configure SSH key authentication
- Add a firewall rule
- Configure time synchronization
- Troubleshoot DNS resolution
# ============================================
# PART 5: STORAGE TASKS
# ============================================
- Create an LVM volume
- Mount a filesystem persistently
- Add swap space
- Configure NFS
- Extend a logical volume
# ============================================
# PART 6: ESSENTIAL COMMANDS TASKS
# ============================================
- Find files matching criteria
- Archive and compress files
- Create a systemd service
- Troubleshoot disk space
- Configure SSL certificate
# ============================================
# PART 7: USERS AND GROUPS TASKS
# ============================================
- Create a user with specific properties
- Configure resource limits
- Set ACLs on a file
- Configure environment profiles
# ============================================
# PART 8: TASK TIME BUDGET
# ============================================
17-20 tasks in 120 minutes
Average: 6-7 minutes per task
Quick tasks: user creation (1 min)
Complex tasks: LVM + mount (5-10 min)
Reverse proxy: (10-15 min)
# ============================================
# PART 9: VERIFICATION PATTERNS
# ============================================
User: id username
Service: systemctl status service
Mount: df -h, findmnt
Firewall: ufw status, firewall-cmd --list-all
Network: ip addr, ip route
Storage: lvs, vgs, pvs, lsblk
# ============================================
# PART 10: COMMON TASK MISTAKES
# ============================================
- Not persisting the change
- Misreading the UID or port number
- Forgetting to enable a service
- Not verifying the result
- Spending too long on one task
- Not reading the task completely
The ten parts summarized the exam logistics, domain weights, task examples, time budget, verification patterns, and common mistakes.
Quick Reference
Exam Details
| Item | Value |
|---|---|
| Duration | 120 minutes |
| Tasks | 17–20 |
| Passing Score | 67% |
| Format | Performance-based |
| Proctoring | PSI Secure Browser |
| Validity | 24 months |
| Cost | $395 (with retake) |
Domain Weights
| Domain | Weight |
|---|---|
| Operations Deployment | 25% |
| Networking | 25% |
| Storage | 20% |
| Essential Commands | 20% |
| Users and Groups | 10% |
Verification Commands
| Task Type | Verification |
|---|---|
| User | id username |
| Service | systemctl status name |
| Mount | df -h, findmnt |
| Firewall | ufw status, firewall-cmd --list-all |
| Network | ip addr, ip route |
| Storage | lsblk, lvs, vgs, pvs |
| Cron | crontab -l |
Time Budget
| Task Complexity | Time |
|---|---|
| User/group creation | 1–2 min |
| Firewall rule | 1–2 min |
| Service configuration | 3–5 min |
| LVM + mount | 5–10 min |
| Reverse proxy | 10–15 min |
| Network troubleshooting | 5–10 min |
Best Practices
✅ Do This:
# Read the task completely
Read twice before starting # ✅
# Verify the result
Check the state after completing the task # ✅
# Persist changes
Add to /etc/fstab, use --permanent, enable services # ✅
# Use man pages
The exam allows documentation # ✅
# Practice with a timer
Simulate the 6-7 minute per task average # ✅
# Move on if stuck
Return to difficult tasks later # ✅
# Use the exam simulator
Killer.sh provides 20-25 practice questions # ✅
❌ Don’t Do This:
# Don't assume you remember the task
Re-read it after completing # ❌
# Don't skip verification
A partially correct task is a failed task # ❌
# Don't forget persistence
A mount without /etc/fstab will not survive reboot # ❌
# Don't spend 30 minutes on one task
Time is limited # ❌
# Don't ignore the domain weights
Operations and Networking are 50% combined # ❌
# Don't rely on memorization
Know where to find the information # ❌
# Don't cram
Practice consistently over weeks # ❌
Common Pitfalls
| Pitfall | Why It Happens | Fix |
|---|---|---|
| Task failed despite effort | State not verified | Check the result |
| Ran out of time | Stuck on one task | Move on, return later |
| Change lost after reboot | Not persisted | Add to /etc/fstab, enable service |
| Misread UID or port | Skimmed the task | Read twice |
| Service not started | Forgot systemctl start | Start and enable |
| Firewall rule not permanent | Forgot --permanent | Add and reload |
| Mount not persistent | Not in /etc/fstab | Add entry |
Real-World Examples
1. Create a User
useradd -m -s /bin/bash -u 1500 alice
id alice
2. Configure a Firewall Rule
# Ubuntu
ufw allow 80/tcp
ufw status
# CentOS
firewall-cmd --add-port=80/tcp --permanent
firewall-cmd --reload
firewall-cmd --list-all
3. Create an LVM Volume
pvcreate /dev/sdb
vgcreate myvg /dev/sdb
lvcreate -L 10G -n mylv myvg
mkfs.ext4 /dev/myvg/mylv
mount /dev/myvg/mylv /mnt/data
echo '/dev/myvg/mylv /mnt/data ext4 defaults 0 0' >> /etc/fstab
df -h /mnt/data
4. Create a Systemd Service
cat > /etc/systemd/system/myapp.service << EOF
[Unit]
Description=My App
After=network.target
[Service]
ExecStart=/usr/local/bin/myapp
Restart=always
[Install]
WantedBy=multi-user.target
EOF
systemctl daemon-reload
systemctl enable --now myapp
systemctl status myapp
5. Configure Time Synchronization
# Ubuntu
timedatectl set-ntp true
timedatectl status
# CentOS
systemctl enable --now chronyd
chronyc sources
6. Set ACLs
setfacl -m u:alice:rw file.txt
getfacl file.txt
7. Find Files
find /var/log -name "*.log" -mtime -7
8. Archive Files
tar -czpf /backup/logs.tar.gz /var/log
9. Configure SSH Key Auth
ssh-keygen -t ed25519
ssh-copy-id user@host
10. Extend a Logical Volume
lvextend -L +5G /dev/myvg/mylv
resize2fs /dev/myvg/mylv
df -h
Visual
Domain Weight Distribution
┌─────────────────────────────────────────────────────────────┐
│ LFCS DOMAIN WEIGHTS │
│ │
│ Operations Deployment ████████████████████████████ 25% │
│ Networking ████████████████████████████ 25% │
│ Storage ██████████████████████ 20% │
│ Essential Commands ██████████████████████ 20% │
│ Users and Groups ██████████ 10% │
│ │
│ Passing score: 67% │
│ Operations + Networking: 50% of the exam │
│ │
└─────────────────────────────────────────────────────────────┘
Task Time Budget
┌─────────────────────────────────────────────────────────────┐
│ 120 MINUTES FOR 17-20 TASKS │
│ │
│ Average: 6-7 minutes per task │
│ │
│ Quick tasks (1-2 min): │
│ - Create user │
│ - Firewall rule │
│ - Set hostname │
│ │
│ Medium tasks (5-10 min): │
│ - LVM + mount │
│ - Service configuration │
│ - Network troubleshooting │
│ │
│ Complex tasks (10-15 min): │
│ - Reverse proxy │
│ - RAID setup │
│ - LDAP integration │
│ │
│ Move on if stuck. Return later. │
│ │
└─────────────────────────────────────────────────────────────┘
Verification Flow
┌─────────────────────────────────────────────────────────────┐
│ PERFORM THE TASK │
│ │ │
│ ▼ │
│ VERIFY THE STATE │
│ │ │
│ ├── User: id username │
│ ├── Service: systemctl status │
│ ├── Mount: df -h, findmnt │
│ ├── Firewall: ufw status, firewall-cmd --list-all │
│ ├── Network: ip addr, ip route │
│ └── Storage: lsblk, lvs, pvs │
│ │ │
│ ▼ │
│ STATE CORRECT? │
│ │ │
│ ├── YES ──▶ Move to next task │
│ │ │
│ └── NO ──▶ Fix and re-verify │
│ │
└─────────────────────────────────────────────────────────────┘
Persistence Checklist
┌─────────────────────────────────────────────────────────────┐
│ DOES THE CHANGE SURVIVE REBOOT? │
│ │
│ Mount → /etc/fstab entry │
│ Service → systemctl enable │
│ Firewall → --permanent + reload │
│ Network → netplan YAML or nmcli con mod │
│ Kernel param → /etc/sysctl.d/ │
│ Cron → crontab -e (saved) │
│ User/group → persistent by default │
│ Swap → /etc/fstab entry │
│ │
│ If the task says "persist" or "after reboot", │
│ the change must be in a configuration file. │
│ │
└─────────────────────────────────────────────────────────────┘
Summary
| Item | Value |
|---|---|
| Duration | 120 minutes |
| Tasks | 17–20 |
| Passing Score | 67% |
| Format | Performance-based |
| Proctoring | PSI Secure Browser |
| Validity | 24 months |
| Documentation | man pages available |
| Operations Deployment | 25% |
| Networking | 25% |
| Storage | 20% |
| Essential Commands | 20% |
| Users and Groups | 10% |
Key takeaways:
- The LFCS is a performance-based exam. You perform tasks on a live Linux system. The grading is automated and checks the state of the system. There is no partial credit for effort.
- The exam has 17–20 tasks in 120 minutes. The average time per task is 6–7 minutes. Some tasks are quick; some are complex. Time management is part of the exam.
- The passing score is 67%. You do not need to complete every task perfectly, but you need to complete enough. The tasks are weighted by domain.
- Operations Deployment and Networking are 25% each. Together they are half the exam. Storage and Essential Commands are 20% each. Users and Groups is 10%.
manpages are available. The exam tests your ability to find and apply information, not your ability to memorize it. Know how to use the documentation.- Verification is part of every task. After performing an action, check that the system is in the expected state. The grading script checks the state, and your verification should match.
- Persistence is often required. Many tasks require changes that survive a reboot. A mount must be in
/etc/fstab. A firewall rule must be permanent. A service must be enabled. Read the task to determine whether persistence is required.
Remember: The LFCS is a test of what you can do, not what you know. The exam gives you a system and a task list, and you have two hours to make the system match the tasks. The format rewards practice, speed, and verification. The chapters that follow cover each domain in detail, with the commands, the configuration files, and the patterns that the tasks require. The goal is not to memorize every flag but to be able to perform each task and verify the result under time pressure. Practice in a real terminal, use the exam simulator, and read each task completely before starting.
Stop using slow, ad-bloated tool sites! 🤮
🔎 Search “KandZ Tools” on Google to use many professional utilities for free.
KandZ.me is the ultimate minimalist hub for:
✅ Finance (Mortgage, Interest, Inflation)
✅ Tech (Base64, JSON, Dev Suite, IP)
✅ Health (BMI, BMR, TDEE)
✅ Productivity (Timer, Workspace, QR)
⚡️ Fast & Private
🔒 No data leaves your device
💎 100% Free
🔗 Use it now: https://tools.kandz.me
🔖 Bookmark it—you’ll need it later!